Fablegrove is now Tinker. Same people, same stories, new name.
Privacy, in plain words
Privacy policy.
Last updated 4 October 2026.
Tinker is operated by DesignHub LLC. Tinker was called Fablegrove until October 2026. This policy explains what we collect when you use fablegrove.ai and the app at app.fablegrove.ai, why, who helps us look after it, how long it is kept, and the choices you have. When it says “we” or “us”, it means DesignHub LLC, which is responsible for your information. It sits beside our Terms of service.
In short: we collect what we need to keep your account and make your stories, we share it only with the services that help us do that, we never sell it, and you can ask us to see, change or delete it at any time.
1. What we collect
Your account
We use Better Auth to manage sign-in and the cookies that keep you signed in. You can use an email code or Google. Google sign-in shares your name, email address, profile picture, and account identifier with us so we can create or recognize your Tinker account. It does not give us access to your Gmail, Drive, or calendar.
Your profile holds the name, picture and short introduction you choose to add in Settings. Each time you sign in, we keep the network address and the kind of browser the sign-in came from with that session, to help keep your account safe.
Your account, saved stories, and credit usage are stored to provide your library and track your remaining story credit. Account records are stored in our Neon database, and recordings in private Cloudflare storage. Authorized administrators can review account and usage records to provide support and reconcile costs.
Your stories
Everything you make is kept in your account: your ideas, the stories Sprig writes and every change you make to them, your characters and the pictures Sprig draws for them, your shelves, what you and Sprig say to each other while you work on a story, and the recordings of it read aloud with its music and sound effects, including any you make in your own voice (see Recordings of your voice). Stories are often about the children they are for, so put in only what you are comfortable with: a first name is plenty.
We also note when each story is played in the app, which part of it, whether it was played to the end, and for how long, leaving out any time it was paused. Authorized administrators can read the ideas you ask Sprig for and these counts, to see what families make and listen to and to make Sprig better. They are never shown to anyone else.
When you send a story to a friend, we keep a copy of it for the link, with your name as the sender, your note, and the name of your friend’s child if you chose to write one in, so the link keeps working even if you change or delete the original. You can take it back at any time in Settings → Friends, and the link stops working.
Subscriptions
Stripe hosts Checkout and the billing portal. We share your account email and an internal account reference with Stripe to manage your subscription. Stripe collects your payment and billing details on its own pages; Tinker does not receive your full card number. We store Stripe customer, subscription, and invoice references, payment status, and the credit your payment provides.
For purchases sold through Link using Stripe Managed Payments, Link is the merchant of record and handles receipts, transaction support, refunds, and applicable tax collection. Link processes your billing information under its privacy policy and purchases are subject to its terms and refund policy. Tinker provides support for your account and stories.
You can update payment details and cancel renewal through the billing portal. Cancelling renewal keeps your paid credit available until the end of its paid period. Billing and usage records may remain for accounting, support, and abuse prevention.
Trying a story
Sprig writes your draft using Anthropic’s service, so your story idea and any changes you ask for are sent there. When you press Play, narration and character lines are sent to Cartesia, sound descriptions and custom music descriptions to ElevenLabs through fal.ai, and a few words from each chapter’s music description to the Lots of Sounds music library as a search. Please leave children’s identifying details out of demo stories.
Demo recordings are cached in private Cloudflare storage so you can listen again. Playback links expire after an hour; the cached recordings currently remain until removed. We use a keyed hash of your network address to separate custom demo recordings. We do not put your raw network address in those cache records. The prepared example and catalogue sound effects are shared between visitors. Each chapter’s music is picked from the Lots of Sounds library, or composed if you ask for a custom piece, and kept for replay.
For stories tried without an account, we record the network address and approximate country supplied by Cloudflare with our internal usage and cost records. Only authorized administrators can view these details. New writing and recordings are limited per network address over a rolling 24 hours. The temporary limit records expire after 24 hours; the usage records remain for accounting and abuse prevention. Replaying cached audio uses no new allowance.
We keep the idea you type and each change you ask Sprig for, with the title Sprig gave the story, how long it took to write and whether it was finished, where you asked (the homepage or the app), and, without an account, the approximate country Cloudflare places you in. We also count each time the story is played, and for how long. Only authorized administrators can read these, to see what families ask for and to make Sprig better. If you keep the story, they join it in your account.
The story you try is kept in your own browser, and nowhere else, so it is still there if you reload the page. It stays until you replace it with another story or clear this site’s data from your browser.
How you found us
If you arrive from one of our search ads, the address carries an ad click reference from Google and the name of the ad. We keep those, with the address you landed on, in a cookie on fablegrove.ai for up to ninety days so that, if you make an account, we can tell which ad brought you and report to Google that its click led to an account, a first story, or a paid plan. The report carries the click reference only, never your name, email address, or anything you wrote. The cookie is cleared as soon as an account claims it, and nothing about it is ever shown to another family.
If you draw icons with Tinker Icons after arriving from one of our ads, we also keep the click reference and the name of the ad beside what you asked Sprig to draw, so we can count how many visits from each ad went on to draw icons, whether or not you ever make an account. That count is our own and is not reported to Google.
Which pages are used
We count how often each page is opened, and by how many visitors a day, so we can see which pages are used. The count is our own: it sets no cookie, goes to nobody else, and keeps nothing about who was looking. A visitor is told apart for one day only, by a scrambled value made from the day, their network and their browser’s name, which cannot be turned back into either and is thrown away two days later.
Asking for help
When you ask for help in the app, we keep what you write, any pictures or files you attach, the page you were on, and the email address to answer, so you can read your request and our reply together later. If you write to hi@fablegrove.ai, we keep your email and our answer.
When you send feedback from Tinker Icons, we keep what you write, the page you were on, your browser’s random icon maker identifier, and an email address only if you give one so we can answer. If you are signed in, it is kept with your account, and our reply appears under Help in the app as well. Pacing uses the same one-way, keyed hash of your network address as drawing does.
When something goes wrong
If a page or a request fails, we record what went wrong so we can put it right: the error itself, the page’s address, your browser’s name, language and screen size, the approximate country, the last few things tapped in the app, and, if you are signed in, your account’s reference, email address and plan. We never record a story’s words, your cookies, or your sign-in details with it.
Yoto
If you connect your Yoto account, Yoto tells us your Yoto account’s reference and name, and gives us keys to your Yoto library, which we keep so we can put stories on your cards when you ask. When you send a story, Yoto receives its title, description and cover picture, and each chapter’s title, audio and icon.
Tinker Icons
Our free icon maker at icons.fablegrove.ai needs no account to start. When you save icons while signed in, we keep private copies, including any animation, in your account so you can use them in stories and on other devices. When you ask Sprig to draw, we keep what you typed (your idea, or your track titles), the icons Sprig draws with a name and a short description for each, whether you chose to add them to the public library, the approximate country, a random identifier your browser makes up so your icons can be told apart from anyone else’s, and, if you arrived from one of our ads, the click reference and the name of the ad described under How you found us. We also count what is done with the icons, such as downloads, edits and searches, against that identifier. As with trying a story, the usage records keep the network address a request came from, and pacing uses a one-way, keyed hash of it.
Drawing without an account is limited per network address, by what it costs us rather than by a number of icons, and the limit is counted over everything drawn from that address, not by the day; past it the maker offers you a free account, which lifts it. While you are signed in, your browser is given a short-lived pass saying only which account it belongs to and when it runs out, so the maker — which answers at a different address from the app and cannot see your sign-in — can tell that you have an account. If you make an account later, the note described under Cookies lets us record that the icon maker is how you found us.
Icons in the public library can be found and downloaded by anyone, and Tinker may use them elsewhere in its own apps. Untick “Add to the public library” before Sprig draws to keep your icons to yourself, or take an icon back out afterwards. We keep pictures of other people’s characters and brands out of the library; if one slips through, tell us and we’ll take it down. A picture you turn into an icon stays in your browser and is never sent to us.
If you make a link out of your icons to send to someone, we keep a copy of those icons and the words you asked for, under a short code that only appears in the link, and we count how many times the link is opened and how many of the people who open it keep the icons in their own browser. Anyone who has the link can see what it holds, so only send it to people you mean to. The copy is taken when you make the link: editing your icons afterwards, or taking them out of the public library, does not change what the link shows. You can take a link back at any time under “Links you’ve sent” in the maker, which deletes our copy and stops the link working; anyone who already saved those icons to their own device keeps them. Keeping icons somebody sent you writes them to your own browser’s storage and needs no account.
So that icons in the public library can be found by what they show and not only by their exact words, each one’s name, description and set title are sent to OpenAI to suggest other words people might search for and to be turned into numbers that can be compared, and so are the words you type into the library’s search. The icons themselves, your identifier and anything else about you are not. Each shared icon is also published as a picture file at its own address on cdn.fablegrove.ai, so it can be shown and downloaded anywhere; taking it out of the library removes that file.
The icon API
Anyone can search the public icon library from their own app or website through our free API at api.fablegrove.ai, with no account or key. For each request to it we keep the search words, the time, what was answered and how quickly, the network address it came from and what Cloudflare tells us about that address (the approximate country, region and city, and the network provider), the address of the website calling it (only the site, never the page or anything after it), the browser’s or app’s description of itself, and Cloudflare’s reference for the request. We never keep cookies or sign-in details from these requests. We use these records to keep the API working and fair for everyone, to stop abuse, and to learn which icons people look for and cannot find. Only Tinker’s administrators can see them. Search words are also sent to OpenAI, as described above.
Earlier access requests
If you previously applied for early access, your email address, introduction, submission time, and consent to application emails, invitations, and project updates remain stored in our Neon database. The application process has ended; you can now create an account directly.
To limit automated submissions, we used a temporary, one-way, keyed hash of your network address and a request count. We do not store your raw network address with application records. Our hosting provider may process technical request logs to operate the site.
2. Why we use it
We use what we collect only to:
- run your account and your library: sign you in, keep your stories, and have Sprig write, read aloud, compose and draw what you ask for;
- bill you, keep your story credit right, and look after refunds and disputes;
- answer you when you ask for help, and send the emails the service needs: sign-in codes, replies to your help requests, and a short letter when a friend you sent a story to makes their first story;
- keep Tinker safe and fair: pace how much can be made, stop abuse, and find and fix what breaks;
- see which pages are used and which ads brought families to us, in the ways described above;
- meet our legal duties, such as keeping accounting records.
We don’t use your stories to advertise to you, we don’t build profiles of you or your children, and we don’t sell your information.
If you are in the EU or the UK, the law asks us to name our reasons. Most of this is needed to provide the service you signed up for. Keeping things safe, fixing what breaks, counting pages and measuring our ads are our legitimate interests, which we have weighed against yours. Keeping accounting records is a legal obligation. Where we ask for your consent, such as for project update emails, you can withdraw it at any time.
4. Recordings of your voice
You can choose to tell a story in your own voice, reading it aloud in the app a page at a time. Those recordings are yours, and we look after them like this:
- What we keep. One recording for each page you read, kept in private storage with our storage provider, Cloudflare, and a note in our database of which page it is and how long it runs. They are private to your account.
- Who hears them. Only you, and whoever you play or send the story to. If you send the story to your Yoto library, its audio, your voice included, goes to your Yoto library, because that is what you asked to send.
- Where they never go. These page-by-page recordings are never sent to the services that help write or voice stories (Anthropic, Cartesia and ElevenLabs), and are never used for training, or to make a copy of your voice.
- No voice copies. Tinker doesn’t clone voices. If that were ever offered, it would be a separate choice you would have to opt into, and recording a story would never sign you up for it.
- Deleting them. In the recorder you can delete one page’s recording, record a page again (the old recording is deleted when the new one is kept), or delete every recording for a story at once. Deleting a chapter, a story or your account deletes its recordings too.
- Your microphone. The app uses it only while you are recording, once your browser has asked you. The website and Tinker Icons never use it.
Recordings from family
You can make a link in Tinker and send it to a grandparent, a friend or anyone you would like to hear from. They open it on their phone or computer, record a message or a story, and it arrives in your inbox. They don’t need an account, and they don’t install anything. Here is how we look after what they record.
- Who records. Anyone who has the link. The link is long and hard to guess, and you can close it at any time; after that, anyone who opens it is told it is closed, and nothing more can come in through it. Recordings it had already brought stay in your inbox.
- What we ask them first. Before the microphone is touched, the page tells them who is asking, what happens to their recording and for how long, and asks them to tick a box saying they are happy for your family to keep it and play it to your children. Nothing is recorded until they do. We keep a note of which version of those words they agreed to, and when.
- What we keep. The recording itself (the sound, in private storage with our storage provider, Cloudflare), how long it runs, the name they chose to type (which is optional), when it arrived, and which of your links it came through. We keep no other details about them. To stop one person sending a great many recordings, we count recordings by network address for a short while; we do not keep that count against their name or the recording.
- Who hears them. Only your family, in your Tinker account, and whoever you play them to. If you add a recording to a playlist and save it to Yoto, its audio is copied into your Yoto library, because that is what you asked for. We never share a recording with anyone else.
- Where they never go. A relative’s recording is never sent to the services that help write or voice stories, never used for training, and never used to make a copy of anyone’s voice.
- How long we keep them. A recording is deleted 90 days after it arrives if you never add it to a playlist, and 30 days after you add it to one (by then its audio is on Yoto). The inbox shows the day each one will be deleted.
- Deleting them sooner. You can delete any recording from your inbox at any time, and its audio is deleted with it. Closing a link doesn’t delete what it brought; deleting your account deletes everything. A relative has no account, so they can’t delete a recording themselves: they can ask you, or write to us at the address at the end of this policy, and we will delete it for them.
- Their microphone. The page uses it only while they are recording, once their browser has asked them. The page sets no cookies and adds no tracking: it is counted as an opened page like any other page of the app, without the secret part of its address.
5. Uploaded audio stories
When you choose Upload or record audio to create a new story, we prepare the recording and turn it into editable words and chapters. This is a separate choice from reading an existing story a page at a time.
- What we keep. Your original file, prepared chapter audio and any cover you keep are stored privately with Cloudflare. The words, timings, titles and corrections are kept in our database. The original recording is kept with a saved story. Unfinished uploads are removed after 30 days without being opened or changed. Optional sound cleanup preserves its duration and does not automatically cut words, pauses or breaths. Deleting the story removes these files and words. We keep internal file references for ongoing cleanup, without the recording or its words, so an upload that finishes after deletion can still be removed.
- Who processes it. Audio preparation and optional noise reduction run on Cloudflare. Prepared audio chunks go to Cartesia for words and timings. The transcript goes to Sprig’s service to suggest chapters and titles, and short chapter descriptions help the icon maker draw icons. Asking for a cover sends your cover description to fal.ai and its image service. Uploading your own cover does not ask an image service to draw one. Tinker does not clone your voice.
- On your phone. While you record, audio chunks are kept in this browser so a closed screen does not lose the recording. They are removed after a successful upload or when you delete the phone recording. Unsaved review edits are also kept in this browser, separately for each account, and can be restored or deleted when you open the recording. Clearing browser storage removes these local copies. A shared device may retain them between visits.
- Copies you send. Sending a story to Yoto transfers its chapter audio, titles, icons and cover to your linked Yoto account. Files you download or send remain wherever you keep them, including after removing the story from Tinker.
6. Children’s information
Tinker is for grown-ups. Accounts are for people who are 18 or older, and children enjoy Tinker only through a parent, carer or teacher. We don’t knowingly collect personal information from children, and nothing on the site or in the app asks a child for it.
Stories are often about children and may include a child’s name, age or interests if you write them in. That information belongs to you, is used only to make and play your stories, and is never used to advertise or to build a profile. When you send a story to a friend, their child’s name is optional, and is kept only in the copy of the story you sent.
If you believe a child has given us personal information, write to hi@fablegrove.ai and we will delete it.
8. How long we keep things
- Your account, stories and recordings: for as long as your account is open. When you ask us to close your account, we delete them, apart from the records below that we need to keep.
- Recordings of your voice: until you delete them, or the story or account they belong to.
- A story you sent to a friend: until you take it back.
- Sign-in codes: ten minutes. Signed-in sessions: until you sign out, or 30 days without a visit.
- Billing, story credit and usage records: for as long as we need them for accounting, tax, support and abuse prevention, which can be several years after an account is closed.
- Stories tried without an account: the temporary limit records expire after 24 hours; the usage records remain for accounting and abuse prevention, and so do the ideas and changes you asked Sprig for and the counts of plays, unless you keep the story, when they join your account. Demo recordings currently remain until removed.
- Page counts: the scrambled value that tells a visitor apart is thrown away two days later.
- Icons made with Tinker Icons: in Tinker’s icon library. Shared icons stay public until you take them out or we remove them; what you typed, your browser’s identifier, any ad click reference kept with an ask, and the usage records stay with them for accounting and abuse prevention.
- Links you make out of your icons: the copy of the icons, the words you asked for, and the counts of opens and keeps remain until you take the link back, or ask us to remove it.
- Icon API request records, with the network address and location: ninety days, then deleted. Counts that name no one (how many searches, from which countries, for which words) may be kept longer.
- Error reports: thirty days.
- The ad click cookie, and the icon maker’s arrival cookie: up to ninety days each, or until an account claims them.
- Help requests: with your account, so you can read them again, until you ask us to delete them.
- Earlier access applications: until you ask us to remove them.
9. Your rights and how to use them
Everyone
Wherever you live, you can ask us to:
- show you the information we hold about you, and give you a copy of it;
- correct anything that is wrong (you can change your name, picture and introduction yourself in Settings → Profile);
- delete it (you can delete any story from its menu, and take back a story you sent to a friend in Settings → Friends; we close your account and delete the rest when you ask);
- send you your stories and account information in a common format you can take elsewhere.
For questions about your account or a request to access or remove your information, email hi@fablegrove.ai from the address you sign in with, so we know it is you. We will answer within 30 days, and it costs nothing. If the law requires us to keep something, such as a billing record, we will tell you.
We do not sell your personal information, and we will never treat you differently for using your rights.
You can ask to access or remove an earlier application by replying to a Tinker email or contacting us below. Project update emails will include a way to unsubscribe. We do not sell your email address or application details.
In the EU and the UK
You also have the right to restrict or object to how we use your information, including where we rely on our legitimate interests, to have it moved to another service, and to withdraw any consent you have given. If you are unhappy with our answer, you can complain to your local data protection authority; in the UK, that is the Information Commissioner’s Office.
In California
You have the right to know what personal information we collect, use and disclose, to have it deleted or corrected, and to opt out of its sale or its sharing for cross-context behavioral advertising. We do not sell personal information or share it for that kind of advertising, and we don’t use sensitive personal information to infer anything about you. You can use these rights yourself, or through someone you authorize, by writing to hi@fablegrove.ai.
In Australia
We handle personal information in line with the Australian Privacy Principles. You can ask to see and correct what we hold about you. If you have a complaint, write to us first and we will answer within 30 days; if you are not satisfied, you can take it to the Office of the Australian Information Commissioner.
10. Where it is processed
DesignHub LLC is based in the United States, and so are most of the services listed above. Cloudflare serves the site and the app from places close to you and keeps the recordings in its storage, and Neon keeps our database. Your information is therefore processed in the United States and in the other countries where these services operate, whose data protection laws may differ from yours. Where the law requires it, we rely on the safeguards these services offer for international transfers, such as standard contractual clauses.
11. Security
- Every page and request travels over an encrypted connection, and so does the app’s connection to our database.
- Recordings are kept in private storage, and the links that play them expire after an hour.
- The keys Google gives us when you sign in with it are stored encrypted.
- We never receive your full card number: Stripe and Link take it on their own pages.
- Only a few authorized administrators can see account and usage records, and only from an address on a short list.
No system is perfectly secure. If something happens that puts your information at risk, we will tell you, and the authorities, as the law requires.
12. Changes to this policy
We will update this policy when Tinker or the law changes, and change the date at the top when we do. If a change matters to you, such as a new use of your information or a new service it goes to, we will tell you by email or in the app before it takes effect.
13. Contact
For anything about your privacy or this policy, write to hi@fablegrove.ai.
DesignHub LLC, Nevada, United States.